Back to skill

Security audit

game-market

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent marketplace-search purpose, but it embeds reusable YY API signing material and uses broad triggers that can cause external marketplace queries with weak user intent.

Review this before installing. It queries a third-party marketplace using embedded signing material and a shared device identifier, and its broad triggers may contact YY when you only mention certain games or trading terms. Prefer explicit invocation, avoid using it for sensitive account decisions, and install only from a pinned, trusted revision.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:88
Finding

Reusable API Signing Secret and Fixed Client Identifier Embedded in Skill Instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:27
Finding

Unpinned Installation Through Mutable Remote Sources

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to install and run a remote package via npx skills without pinning an exact version or immutable reference. If the referenced package or its dependency resolution changes or is compromised, users may execute unintended code during installation or use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger examples include broad phrases such as '买账号' and 'sell account'-style commerce terms that can easily appear in ordinary conversation, causing the skill to activate unintentionally. In this skill's context, accidental activation is more concerning because it can query a third-party marketplace and guide users toward external trading flows, increasing privacy and phishing/external-site exposure risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Overly broad triggers such as generic game-trading and commerce terms can cause the skill to activate in conversations that are not explicitly asking to use this marketplace. Unintended activation increases the chance of unsolicited external requests, marketplace redirection, or execution of browsing/open actions in the wrong conversational context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill hard-codes an API signing secret and instructs the agent to use it to access a third-party service. Embedding reusable credentials in distributable skill content exposes the secret to anyone who can read the file, enabling unauthorized API use, abuse of the provider's front-end trust model, and possible rate-limit or account impact against the service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation logic says to trigger merely on mentioned keywords or game names, without requiring a clear request to search the YY marketplace. This weak intent gating can cause the skill to run when a user is just discussing a game, leading to unnecessary third-party queries or browser navigation that the user did not actually request.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
78% confidence
Finding

The short trigger '代练' is broad enough to appear in general discussion unrelated to invoking this specific skill. In context, short ambiguous triggers contribute to accidental activation and unintended external marketplace lookup behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The trigger set and workflow are heavily tailored to Chinese terms and a YY marketplace context, but the document does not explicitly offer the user a language or locale choice. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy issue unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
78% confidence
Finding

The short trigger '陪练' may be used in ordinary conversation and is not specific enough to indicate intent to use this marketplace skill. Because the skill can make network requests and open browser pages, accidental activation has modest but real security and safety implications.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
76% confidence
Finding

The trigger '道具' is a generic noun likely to occur in many gaming conversations that have nothing to do with a trading marketplace. This increases the chance of the skill activating without clear user intent and initiating third-party queries unnecessarily.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
70% confidence
Finding

Overly Broad Trigger: '崩坏' is too short and may match unintended inputs

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
70% confidence
Finding

Overly Broad Trigger: '原神' is too short and may match unintended inputs

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
80% confidence
Finding

The trigger '游仓' is short and brand-adjacent but still ambiguous enough to match casual references without a clear request to use the skill. In a skill that can browse and open external pages, such ambiguity increases the likelihood of unintended execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.